What the vulnerability does
01Description
Missing Authorization vulnerability in LearningTimes BadgeOS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BadgeOS: from n/a through 3.7.1.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in LearningTimes BadgeOS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BadgeOS: from n/a through 3.7.1.6.
Explanation of Vulnerability in Simple Terms
BadgeOS through version 3.7.1.6 lacks proper authorization checks, allowing authenticated users with low privileges to trigger denial-of-service conditions. An attacker with a standard user account can make requests that degrade site availability. The vulnerability does not affect data confidentiality or integrity, only system responsiveness.
What an attacker can do
Degrade site performance or availability by making authenticated requests that consume resources.
Potential impact on your site
Site may experience slowdowns or temporary unavailability if an authenticated user exploits this repeatedly.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities